Oracle TNSListener SERVICE_NAME Remote Buffer Overflow Vulnerability
BID:4845
Info
Oracle TNSListener SERVICE_NAME Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 4845 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2002 12:00AM |
| Updated: | May 27 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Next Generation Security Software. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.0.2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 |
| Not Vulnerable: | |
Discussion
Oracle TNSListener SERVICE_NAME Remote Buffer Overflow Vulnerability
TNSListener is a component of the Oracle database, distributed by Oracle Corporation.
A buffer overflow has been reported in the Oracle TNSListener. This buffer overflow may allow a user to remotely execute code on a vulnerable system. This is the result of an error in logging an oversized SERVICE_NAME received as part of a TNS packet.
Reportedly, this issue only exists on versions of Oracle 9.0.x for Microsoft Windows and VM.
This issue was formerly discussed in BID 4955.
TNSListener is a component of the Oracle database, distributed by Oracle Corporation.
A buffer overflow has been reported in the Oracle TNSListener. This buffer overflow may allow a user to remotely execute code on a vulnerable system. This is the result of an error in logging an oversized SERVICE_NAME received as part of a TNS packet.
Reportedly, this issue only exists on versions of Oracle 9.0.x for Microsoft Windows and VM.
This issue was formerly discussed in BID 4955.